Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-11149

Опубликовано: 30 сент. 2025
Источник: redhat
CVSS3: 5.3

Описание

This affects all versions of the package node-static; all versions of the package @nubosoftware/node-static. The package fails to catch an exception when user input includes null bytes. This allows attackers to access http://host/%00 and crash the server.

A denial of service flaw has been discovered in the node-static npm package. The package fails to catch an exception when user input includes null bytes. This allows attackers to access http://host/%00 and crash the node server.

Отчет

The availability risk of this vulnerability is limited to the web server which incorporates the node-static package. The host system is not at risk.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8mozjs60Not affected
Red Hat Enterprise Linux 9gjsNot affected
Red Hat Enterprise Linux 9polkitNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=2400393node-static: node-static denial of service

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
10 месяцев назад

This affects all versions of the package node-static; all versions of the package @nubosoftware/node-static. The package fails to catch an exception when user input includes null bytes. This allows attackers to access http://host/%00 and crash the server.

CVSS3: 7.5
nvd
10 месяцев назад

This affects all versions of the package node-static; all versions of the package @nubosoftware/node-static. The package fails to catch an exception when user input includes null bytes. This allows attackers to access http://host/%00 and crash the server.

CVSS3: 7.5
debian
10 месяцев назад

This affects all versions of the package node-static; all versions of ...

CVSS3: 7.5
github
10 месяцев назад

@nubosoftware/node-static failure to catch exception can result in server crash

5.3 Medium

CVSS3